add-shape-types-to-torch-model

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Command Execution: The skill instructs the agent to run local verification commands, including pyrefly check and a bundled shell script verify_port.sh. These commands are used to perform static analysis and ensure the correctness of the added type annotations, which is the primary purpose of the skill.
  • Indirect Prompt Injection Surface: The skill processes user-supplied PyTorch model code, creating a potential surface for indirect prompt injection. However, the risk is minimized by the skill's prescriptive "gate" system and the use of static analysis checkpoints (reveal_type, assert_type), which focus the agent on technical code structures rather than natural language instructions within the source code.
  • Internal Tooling and Environment: The skill references specific internal paths and build conventions consistent with the vendor's development environment. These references are used to locate stubs and runtime extensions necessary for the shape-tracking functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 07:28 PM